Digital transformation has moved most customer, B2B, and peer interactions online, but identity and access management has not evolved to match modern user behavior. With the typical person maintaining nearly 200 online accounts, password reuse becomes almost inevitable, increasing security risk. More fundamentally, today’s IAM model creates an imbalance: enterprises become the custodians of personally identifiable information (PII) while users must trust companies to handle sensitive data responsibly. This arrangement is increasingly misaligned with shifting expectations, where consumers demand more control and regulations such as GDPR and CCPA pressure enterprises to minimize retained PII.
Self-sovereign identity (SSI) is presented as a philosophy and emerging approach that returns control of identity information to individuals. SSI is often associated with blockchain-based architectures, decentralized identity, and portable digital identity, but SSI specifically requires that the individual meaningfully controls identity. A key technical foundation is blockchain as a “trustless” ledger for credential exchange, backed by digital signatures, hashing, and consensus mechanisms that prevent falsification or alteration. Decentralized public key infrastructure (DPKI) strengthens security by making the individual the sole holder of a private key, but introduces usability risks if keys are lost or compromised. Decentralized Identifiers (DIDs), an emerging W3C standard, aim to standardize registration and communication of DPKI without ceding ownership to third parties.
The Sovrin Network is described as a leading SSI ecosystem governed by the nonprofit Sovrin Foundation (established in 2016), supported by 80+ organizations and global volunteers. Sovrin combines a public permissioned blockchain, Hyperledger Indy/Aries/Ursa, verifiable credentials, zero-knowledge proofs, pairwise DIDs, and governance via trust anchors to legitimize credentials. Strengths include privacy-by-design, interoperability, and standards participation, while challenges include pseudonymity expectations, time-to-sustainability of its DNS-like business model, and multi-device synchronization tradeoffs when credentials are kept on edge devices.
See All Locations
See All Locations